DocuPal is committed to protecting your privacy. This policy explains how we collect, use, store, and protect your information when you use the DocuPal application.
Document text and chat messages are used solely to produce your analysis in real time. Analysis results and history are stored only on your device, encrypted (AES-256-GCM) with keys held in the iOS Keychain. DOCX, XLSX, and CSV files are parsed entirely on-device — only the extracted text is sent for analysis.
DocuPal is not a HIPAA-covered entity and is not certified for classified/government data. Submitting legal, medical, financial, or personal documents is at your discretion; document text is transmitted to third-party AI services for processing. Avoid submitting government-classified material or unnecessary sensitive identifiers.
DocuPal routes AI requests through a secure gateway we operate on Amazon Web Services (AWS), region Asia Pacific (Singapore). Extracted text is sent to the gateway over TLS 1.3; the gateway forwards it to an AI provider and returns the result. The gateway holds all provider API keys server-side and does not persist your text after the request.
Depending on availability, language, and tier, text may be sent to any of: Cerebras, Groq, Mistral AI, Google (Gemini), OpenAI, xAI (Grok), and Anthropic (Claude). Each provider's own policy governs its handling. We do not instruct any provider to retain your data beyond the request (OpenAI may retain API inputs up to 30 days for abuse monitoring). This provider list may change as we optimize the service.
Low-confidence images may be sent to Google Cloud Vision for OCR. Translation uses Apple's on-device framework where available, with Google Translate as a fallback. Read-aloud may use Amazon Polly and Google Cloud Text-to-Speech (which receive the text), with Apple's on-device speech as a fallback.
We use Google Firebase Remote Config to deliver feature flags and limits; it associates an anonymous installation identifier. We use Apple DeviceCheck (a per-device flag, no personal data) to prevent trial abuse. We use no advertising, analytics, or tracking SDKs.
All data lives on your device until you delete it (per-item, or Settings → Reset App Data). Nothing is retained on our servers after processing. You may exercise access, correction, deletion, portability, and consent-withdrawal rights (GDPR, PDPA, CCPA and similar) by using in-app controls or contacting us.
Text is transmitted first to our AWS gateway in Singapore, then to third-party provider servers that may be outside your country. Transfers are protected by TLS 1.3, server-side key custody, minimal data transmission, and no retention instruction. EU transfers rely on Standard Contractual Clauses as applicable to AWS and the providers.
DocuPal is not directed at children under 13 (or 16 in the EU). We do not knowingly collect data from children. Minors aged 13–18 should use the app only with parental consent and supervision.
We may update this policy from time to time. Material changes are communicated in-app and may require re-consent. The version and effective date above will be updated accordingly.
Data-protection contact: srinivassane.r@outlook.com. We aim to respond within 30 days.
DocuPal uses AI and can make mistakes. It is an informational tool only and does not provide legal, medical, financial, or other professional advice. Always verify important information and consult a qualified professional before making decisions. Governing law: Singapore.